CloudTrail is the cornerstone of AWS threat detection — but it has structural blind spots adversaries deliberately exploit. This guide maps 12 places CloudTrail does not log by default, the techniques that abuse each gap, and the compensating hunt patterns that fill the visibility hole.
A 15-month career roadmap for SOC analysts transitioning to threat hunters — five phases of three months each (Mindset, Telemetry, Tradecraft, Hunts, Portfolio), with weekly cadences, success metrics, common pitfalls, and FAQ for working analysts.
The complete 2026 AI glossary — LLM, hallucination, token, training vs inference, fine-tuning, reinforcement learning, distillation, RAG, chain of thought, weights, validation loss, and coding agents. Plain-language definitions plus technical depth plus cybersecurity tie-ins for SOC analysts, threat hunters, and detection engineers.
76,205 indicator observations across 154 adversary clusters. Tor anonymisation network surged to 17% of the catalogue, DPRK activity escalated six-fold, and the Velvet Ant network-appliance APT cluster reappeared. Full MITRE ATT&CK technique pressure, Sigma detection recipes, and platform-ready intelligence.
55,729 indicator observations across 91 adversary clusters this week — featuring Silent Ransom Group, DPRK-aligned activity, VShell, and a Mirai-class IoT seeder wave. Trend analysis, severity breakdown, detection recipes, and the platform to query it all.